Off-by-One Out-of-Bounds Vulnerability in RTKLIB by Tomoji Takasu
CVE-2026-56787
Key Information:
- Vendor
Tomojitakasu
- Status
- Vendor
- CVE Published:
- 25 June 2026
Badges
What is CVE-2026-56787?
RTKLIB versions up to 2.4.3 are susceptible to an off-by-one out-of-bounds read vulnerability, specifically within the decode_ssr3 function. This issue permits remote attackers to instigate a global buffer overflow by transmitting specially crafted RTCM3 SSR messages that include manipulated signal mode fields. By leveraging this vulnerability, malicious actors can disrupt RTKLIB operation, leading to potential denial of service or crash scenarios for both RTKLIB rovers and CORS servers. Effective mitigation strategies are critical to ensure the integrity and availability of systems using RTKLIB.
Affected Version(s)
RTKLIB 0 <= 2.4.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
